Self-Study: Introduction to DevSecOps & Workflows (3.1)

 

Brief

This self-study module covers the fundamental concepts of DevSecOps, its importance in modern software development, and how workflows help automate processes in a secure manner. You will learn how to integrate security into DevOps practices, understand CI/CD workflows, and explore popular tools used in the industry.

Videos

  1. What is DevSecOps?
  2. Learn the core principles of integrating security within DevOps workflows.
  3. Watch: https://www.youtube.com/watch?v=nrhxNNH5lt0&ab_channel=TechWorldwithNana
  4. Introduction to CI/CD Pipelines
  5. Understand the automation of software development using CI/CD workflows.
  6. Watch: https://www.youtube.com/watch?v=scEDHsr3APg&ab_channel=Fireship
  7. GitHub Actions: Introduction
  8. Discover how GitHub Actions can be used to automate and secure software workflows.
  9. Watch: https://www.youtube.com/watch?v=mFFXuXjVgkU&ab_channel=DevOpsJourney

Readings

  1. Introduction to DevSecOps
  2. Explore how DevSecOps integrates security into the software development lifecycle.
  3. Read: https://aws.amazon.com/what-is/devsecops/?nc1=h_ls
  4. DevSecOps Principles and Best Practices
  5. Understand key principles and best practices for implementing DevSecOps.
  6. Read: https://www.sonatype.com/resources/articles/what-is-devsecops
  7. Understanding CI/CD Pipelines
  8. Learn about the components and importance of CI/CD pipelines in software development.
  9. Read: https://www.redhat.com/en/topics/devops/what-is-ci-cd
  10. GitHub Actions Workflow Concepts
  11. Gain insights into how workflows are created and managed with GitHub Actions.
  12. Read: https://docs.github.com/en/actions/about-github-actions/understanding-github-actions

Key Concepts to Explore

  • What is DevSecOps?
  • Incorporating security early in the development lifecycle
  • Continuous security testing and monitoring
  • Collaboration between development, security, and operations teams
  • CI/CD in DevSecOps
  • Automation of code integration and deployment
  • Benefits of continuous integration (CI)
  • Role of continuous deployment (CD)
  • Security Automation Tools
  • Static Application Security Testing (SAST)
  • Dynamic Application Security Testing (DAST)
  • Infrastructure as Code (IaC) security scanning tools
  • GitHub Actions Workflows
  • Workflow structure (triggers, jobs, steps)
  • Using predefined and custom actions
  • Managing secrets securely in workflows

Helpful Links (References)

  1. DevSecOps Implementation Guide
  2. Learn how organizations implement DevSecOps in their workflows.
  3. https://www.btech.id/en/news/implementing-devsecops-a-comprehensive-guide/
  4. Security in CI/CD Pipelines
  5. Discover how to integrate security testing in your CI/CD workflows.
  6. https://snyk.io/platform/ci-cd-pipeline-security/
  7. AWS DevSecOps Best Practices
  8. Understand best practices for securing applications in AWS environments.
  9. https://docs.aws.amazon.com/wellarchitected/latest/security-pillar/sec_ops_devsecops.html

Comments